Ctrl AI launches assisted subject access request review
Teams can now take a subject access request from the first email to a reviewed disclosure bundle, with Ctrl AI proposing what to disclose and redact and a person signing off every document.
What we are launching
Ctrl AI now handles subject access requests. The workflow takes a request from the email or letter it arrives in through to a disclosure bundle and a response letter, and a member of staff reviews every document before anything is released.
Subject access requests land on HR, data protection and complaints teams that already have a day job. Across the sector we see more of them every year, and they are expensive to run. They often arrive alongside a grievance, a complaint or a claim, they ask for “all emails, notes and metadata”, and more of them are drafted with AI. Most of the cost sits in the reading.
Disputes about the responses are rising too. When a response is late, incomplete, over-redacted or not handled in line with ICO guidance, the requester complains and the original request becomes a second piece of work. Data protection complaints to the ICO rose 81% in 2025/26.
From the request to the records
The workflow starts with the request. Ctrl AI proposes who the requester is, what they have asked for, the dates and people involved and the systems likely to hold their data, drawing on the organisation’s own map of where its records live. Staff confirm that assessment before any records are added.

Staff then run the searches and upload what they find, in bulk. Ctrl AI reads every page, including scans and images, and flags exact duplicates, so nobody reads the same email chain six times.
Relevance and redaction, with a reason for each
Each document gets a proposal: disclose, disclose with redactions or withhold, with the reason in plain words. Whole pages can be excluded from a document, and privileged material is flagged for a decision. The guidance behind those proposals combines the ICO’s approach with the organisation’s own rules, for example on naming colleagues and other third parties.
Redaction follows the request. The requester’s own information stays in, other people’s personal data is proposed for redaction under the organisation’s own categories, and people and roles are identified consistently across the whole set of records. A separate step finds the exact text on the page, and anything it cannot locate is flagged for a person to deal with.

Every document signed off
Nothing leaves the platform until a member of staff has recorded a review on every document. Ctrl AI then builds the disclosure bundle, with a cover page, an index and a schedule of the pages disclosed, and drafts the response letter for staff to approve.
Every decision is kept with its reason, and that matters in both directions. A missed redaction is a data breach, and the High Court in Ashley v HMRC (2025) showed that heavy redaction with the context stripped out can also fail. A team that can show why each page was disclosed, redacted or withheld is in a far stronger position if the requester complains to the ICO.
Why we built it this way
Most subject access work is the same set of steps, repeated under a statutory deadline. That makes it a good fit for the approach behind the rest of Ctrl AI: define each task, test it, and keep a person in charge of the decision. Reviewers start every page from a reasoned proposal instead of a blank screen, and the organisation keeps a full record of who decided what.
The workflow is configured for employee, consumer and housing requests, and for FOI, and runs in the same platform as complaints and employment cases. Client data is stored in the UK, Ctrl AI is ISO 27001 certified, and we never use client data to train AI models. Teams can see it work on a sample request using test data.
